Vulnerabilities > Graphql > Graphql > 16.7.1

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2023-26144 Resource Exhaustion vulnerability in Graphql
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries.
network
low complexity
graphql CWE-400
5.3